jfrog / frogbot

🐸 Scans your Git repository with JFrog Xray for security vulnerabilities. 🤖
https://docs.jfrog-applications.jfrog.io/
Apache License 2.0
290 stars 61 forks source link

Couldn't update "org.springframework.ws:spring-ws" to suggested fix version: Version 2.4.4 is not available for artifact #701

Open sulakhesagar opened 1 month ago

sulakhesagar commented 1 month ago

Describe the bug

I am using an Azure pipeline to integrate FrogBot against pull requests and push PR to fix vulnerabilities.

Error message:

[ERROR] Failed to execute goal org.codehaus.mojo:versions-maven-plugin:2.16.2:use-dep-version (default-cli) on project: Version 2.4.4 is not available for artifact org.springframework.ws:spring-ws. [Help 1] [ERROR] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException [ERROR] [ERROR] After correcting the problems, you can resume the build with the command [ERROR] mvn -rf: 11:26:08 [Error] the following errors occurred while fixing vulnerabilities in /tmp/jfrog.cli.temp.-1716283081-1636005597: couldn't update "org.springframework.ws:spring-ws" to suggested fix version: Version 2.4.4 is not available for artifact

[error]Bash exited with code '1'

Current behavior

I am using azure pipeline for integrate FrogBot against Pull Request and Push PR for fix vulnerabilities.

Error message:

[ERROR] Failed to execute goal org.codehaus.mojo:versions-maven-plugin:2.16.2:use-dep-version (default-cli) on project: Version 2.4.4 is not available for artifact org.springframework.ws:spring-ws. [Help 1] [ERROR] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException [ERROR] [ERROR] After correcting the problems, you can resume the build with the command [ERROR] mvn -rf: 11:26:08 [Error] the following errors occurred while fixing vulnerabilities in /tmp/jfrog.cli.temp.-1716283081-1636005597: couldn't update "org.springframework.ws:spring-ws" to suggested fix version: Version 2.4.4 is not available for artifact

[error]Bash exited with code '1'

Reproduction steps

No response

Expected behavior

No response

JFrog Frogbot version

Artifactory 7.77.11 Xray 3.91.3

Package manager info

pom.xml

Git provider

Azure DevOps

JFrog Frogbot configuration yaml file

No response

Operating system type and version

Windows

JFrog Xray version

Xray 3.91.3

eranturgeman commented 1 month ago

Hello @sulakhesagar and thank you for using Frogbot! Can you please provide the following details: 1) Are you working in an air-gapped mode (do you have access to the internet)? 2) Do you have a resolution repository set in your CI execution? meaning do you resolve your dependency from an Artifactory repo or directly from the a central registry? 3) what package manager and programming language do you use? 4) what is the current version of the problematic package you are using?